Tag: unit 42
43 articles

Microsoft Teams Targeted in Voice Phishing Campaigns
Beware of voice phishing scams on Microsoft Teams! A recent campaign, dubbed Spring Ring, used fake IT help desk accounts to trick over 150 employees across 10 organizations into granting remote access.

AI Reshapes Cyber Threat Landscape, Favoring Attackers
The balance of power in cybersecurity has been dramatically upset, with AI capabilities now favoring attackers and rendering traditional defenses obsolete in the face of machine-speed attacks. This marks a generational shift, where attackers have the upper hand and organizations must adapt to keep up.

AI-Enabled Malware Detected but Not Dominant
The surprising truth about AI-enabled malware: despite collecting 405 samples, only 12 actually appeared on customer endpoints, revealing a significant gap in detection. This finding highlights the limited presence of AI-powered threats in the wild.

Kimwolf Botnet Evolves to Evade DDoS Detection
The Kimwolf botnet has levelled up its game with a new upgrade, v7, which uses HTTP/2 floods to mimic real browser traffic, making it super tricky to detect as a DDoS attack. This sneaky move lets the botnet build complete browser fingerprints, blurring the line between legit and malicious traffic.

Identity Compromise Fuels 90% of Cyber Incidents
Nearly 9 out of 10 cyber incidents involve identity compromise, with attackers exploiting weaknesses in credentials, multifactor authentication, and social engineering to gain access to enterprise environments. Identity has become the new front door for cyber threats, making it a critical area of focus for protecting your organization's security.

ChainDrop Worm Exposes npm Ecosystem Vulnerabilities
A sneaky self-propagating worm called ChainDrop has infected over 400 popular npm packages, putting hundreds of millions of downloads at risk each week and threatening developer workstations, CI runners, and cloud instances. This clever malware hides in plain sight by masquerading as legitimate code, making it a formidable foe in the npm ecosystem.

Cybercriminals Exploit AI Tokens for Massive Financial Gains
Cybercriminals are raking in millions by exploiting AI tokens, a technique known as token jacking, which allows them to secretly run up huge bills on unsuspecting companies using commercial AI platforms. In one shocking example, token jacking led to nearly $1 million in unauthorized charges before being caught.

XCSSET Malware Targets macOS Devs Through Compromised Xcode Projects
macOS developers, beware: XCSSET malware is lurking in compromised Xcode projects, infecting unsuspecting victims through a sneaky four-stage infection chain that can deploy 17 distinct modules. This latest variant has been rewritten to dig deep into your workflow and browser, putting your entire development ecosystem at risk.

Malware Exploits Direct IP Connections to Evade DNS-Based Defenses
Nearly half of malware samples with command-and-control activity connect directly to IP addresses, dodging DNS-based defenses and highlighting a significant blind spot in traditional security measures. This alarming trend was uncovered in an analysis of over 4 million dynamic reports, revealing that 45.32% of malicious code uses direct-to-IP connections to evade detection.

Malware Exploits Google Passkey Sync Flaws
Google's passkeys, touted as a secure alternative to passwords, have been found to have flaws that can be exploited by malware, allowing hackers to access sensitive information. Researchers have discovered three techniques, dubbed Pass-ta-key, that let attackers abuse Google Password Manager's synced passkeys on compromised Windows devices.

AI-Powered Attacks Target Vulnerable Servers With Autonomous Exploits
Meet the AI-powered attackers who just took autonomous exploitation to the next level - and here's how researchers uncovered their clever tactics. A China-based threat actor's accidental leak exposed a functional, end-to-end AI-driven attack workflow.

Chinese Hackers Leverage DeepSeek for Autonomous Exploits
Meet the sneaky Chinese hackers who've been using an AI-powered tool called DeepSeek to launch autonomous cyber attacks on over 460 targets - and get a glimpse into their clever tactics. With just a single Telegram instruction, DeepSeek can infiltrate and exploit systems all on its own.

AI Empowers Cyberattacks with Operational Efficiency
As AI continues to evolve, it's crucial to treat AI-driven threats as a top priority, using the technology to supercharge their attacks and compress timelines. AI is being used by attackers to automate routine work, streamline reconnaissance, and shorten development cycles, turning what once took days into operations that can be executed in just hours.

AI Models Expose Millions to Phantom Squatting Phishing Threat
Millions are now at risk of falling prey to a new, rapidly evolving phishing threat called phantom squatting, where attackers exploit AI-generated links to create malicious websites that can evade detection. By registering domains invented by large language models, hackers can create seemingly trustworthy sites that are actually designed to steal sensitive information or spread malware.

LLMs Expose Software Supply Chain to Phantom Squatting Threat
Imagine a hidden threat lurking in the software supply chain, where 250,000 "phantom" domains lie waiting to be claimed by malicious actors - a vulnerability uncovered in a staggering 2.1 million URLs generated by LLMs. This phantom squatting threat has the potential to compromise security, and it's essential to understand its scope and impact.

Chinese Hackers Target Southeast Asia's Energy, Government Sectors
Chinese hackers have launched a stealthy assault on Southeast Asia's energy and government sectors, infiltrating at least ten organizations between October and December 2025. This sophisticated threat, tracked as CL-STA-1062, has been lurking in the shadows since March 2022, using clever tactics like hard-coded encryption keys to evade detection.

Malicious AI Skills Evade Detection on ClawHub Marketplace
Malicious AI skills are slipping through the cracks on ClawHub, with nearly 1 in 5 skills analyzed carrying hidden threats, and a recent audit found a thriving marketplace for bad actors to exploit. Unit 42 uncovered alarming trends, including infostealers and evasion techniques, highlighting the need for vigilance in this rapidly evolving threat landscape.

MacOS ClickFix Attack Exploits Terminal Commands to Spread Infostealer
Beware of a sneaky new attack on macOS, known as ClickFix, that tricks you into pasting a Terminal command, allowing hackers to silently download and launch info-stealing malware on your device. This cleverly crafted scam starts with a fake CAPTCHA page, convincing victims to unwittingly give attackers a backdoor to their sensitive data.

Cloud Providers' Global Namespace Flaw Enables Bucket Hijacking
A newly discovered flaw in cloud providers' global namespace has been exploited in a simple yet powerful bucket hijacking technique, allowing attackers to redirect sensitive data streams into their own accounts. This alarming vulnerability affects multiple services across major cloud providers.

Cybersecurity's 72-Minute Challenge
The clock is ticking: in the blink of an eye, just 72 minutes, attackers can breach your defenses and make off with your data, highlighting a daunting speed gap between threat actors and security teams. This alarming acceleration demands a serious rethink of traditional security operations.

AI Skills Marketplace Exposes Security Gaps
A recent audit of OpenClaw's AI skills marketplace uncovered a staggering 250,706 behavioral deviations in 49,943 agent "skills", revealing a significant gap between what AI skills claim to do and what they actually do. This alarming mismatch highlights the urgent need for robust security measures, such as Palo Alto Networks' Unit 42's Behavioral Integrity Verification (BIV) solution.

Attackers Target Cloud Logging Services for Defense Evasion and Continuous Visibility
Cloud logging services, like AWS CloudTrail and Google Cloud Logging, are a treasure trove of insights into your cloud environment - but they're also a prime target for attackers looking to erase their tracks or gain continuous visibility into your operations. By manipulating these services, adversaries can create persistent blind spots that leave you vulnerable.

Palo Alto Networks Warns of Active PAN-OS Vulnerability Exploitation
Palo Alto Networks has sounded the alarm on a critical PAN-OS vulnerability, CVE-2026-0257, that's being actively exploited by threat actors to bypass authentication and gain unauthorized access to VPN connections. This security gap could allow attackers to circumvent controls and initiate their own VPN sessions, putting your network at risk.

Malvertising Campaign Spreads FlutterShell Backdoor to macOS Users
macOS users beware: a sneaky malware called FlutterShell is spreading through malicious ads and infected desktop apps, allowing hackers to take control of your device and steal sensitive data. This stealthy backdoor can execute commands, access files, and even siphon off browser session info - all while masquerading as legitimate software.